spark
Apache Spark 3.1.1 master node from Bitnami, configured with ACLs enabled and authentication/encryption disabled, exposed on host ports 8080 (localhost) and 443.
docker-compose.yml:3-12install.sh:56-57Cross-site Scripting (XSS) - Stored in nocodb/nocodb
CVE-2022-2022 has a selected CVSS score of 5.4 (medium); EIP currently links 27 repository PoCs and 1 lab environment.
| Product | Source | Version range | Status |
|---|---|---|---|
nocodb/nocodbBrowse nocodb / nocodb/nocodb | CVE List | Before 0.91.7 | affected |
A lab environment that deploys a vulnerable Apache Spark 3.1.1 instance behind an Apache reverse proxy with ModSecurity, designed to demonstrate CVE-2022-33891.
install.sh:1-365The install script explicitly states it is installing a CVE-2022-33891 lab, sets up a vulnerable Spark configuration, and configures Apache with ModSecurity rules referencing the CVE.
install.sh:1install.sh:56-57install.sh:155-156Apache Spark 3.1.1 master node from Bitnami, configured with ACLs enabled and authentication/encryption disabled, exposed on host ports 8080 (localhost) and 443.
docker-compose.yml:3-12install.sh:56-57Apache HTTP server acting as a reverse proxy to the Spark instance on port 8080, with ModSecurity configured in DetectionOnly mode and rules referencing CVE-2022-33891.
install.sh:100-101install.sh:155-156install.sh:160-161Insufficient evidence
No evidence in the supplied files references or describes CVE-2022-2022; it appears only in the repository claim list.
Supported by supplied evidence
The install script explicitly names CVE-2022-33891, configures a vulnerable Spark version, and includes ModSecurity rules designed to detect exploitation of the CVE via the doAs parameter.
install.sh:1install.sh:155-156install.sh:160-161install.sh:18-19install.sh:3install.sh:18-19install.sh:12install.sh:1-365install.sh:155-156install.sh:160-161install.sh:155-161All visible behavior is directed at setting up and exercising the vulnerability lab. The Spark container is bound to localhost for port 8080, and port 443 is mapped for a bind-shell exercise. No hidden, destructive, or externally reaching behavior is observed.
docker-compose.yml:10-12install.sh:1-365This review is limited to the supplied lab evidence packet. It does not assert that the environment runs, reproduces a vulnerability, or is safe to execute. Contract: eip-docker-lab-analysis-v1.